Vulnerability record · CVE-2007-3358 · published 22 June 2007
CVE-2007-3358: SerWeb load_lang.php remote file inclusion allows PHP code execution
Iptel · Serweb
SerWeb 0.9.6 and earlier contains a remote file inclusion flaw in html/load_lang.php, where the _SERWEB[serwebdir] parameter is used to include a remote file without validation. An attacker can point that parameter at a hostile URL and cause the server to execute arbitrary PHP code. The record does not list affected versions beyond '0.9.6 and earlier'.
Description
PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code and a very high EPSS score make exploitation likely, and the flaw yields remote code execution, though the CVSS 2.0 base score is only 6.8.
What it is
SerWeb 0.9.6 and earlier contains a remote file inclusion flaw in html/load_lang.php, where the _SERWEB[serwebdir] parameter is used to include a remote file without validation. An attacker can point that parameter at a hostile URL and cause the server to execute arbitrary PHP code. The record does not list affected versions beyond '0.9.6 and earlier'.
Impact
Successful exploitation gives the attacker arbitrary PHP code execution in the context of the web server, which typically leads to full compromise of the SerWeb host and any data it can reach. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.
Attack surface
Reachable over the network through HTTP requests to html/load_lang.php; the CVSS vector shows no authentication required (Au:N) and medium access complexity (AC:M). No user interaction is indicated by the description or vector.
Exploitation
Not listed in CISA KEV, but EPSS is 0.68011 (99.3rd percentile) and a public Exploit-DB entry (4089) exists, indicating exploit code is publicly available. No ransomware association is documented.
What to do
- Upgrade or patch SerWeb to a version later than 0.9.6; the record does not name a fixed release, so confirm with the vendor.
- If upgrade is not possible, disable or remove html/load_lang.php or restrict access to it.
- Set PHP allow_url_include and allow_url_fopen to Off so remote URLs cannot be included.
- Validate and whitelist the _SERWEB[serwebdir] parameter so it cannot contain a URL or path traversal.
- Isolate the SerWeb host with network controls and least-privilege web server permissions.
Detection
- Search web logs for requests to html/load_lang.php with a URL or external host in the _SERWEB[serwebdir] parameter.
- Alert on outbound HTTP requests from the web server to unexpected external hosts, which may indicate remote include fetches.
- Monitor for unexpected PHP file creation or execution in web-accessible directories on the SerWeb host.
- Review PHP error logs for include or fopen failures referencing remote URLs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3358 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-3358), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.